Skills.
Give your AI a better way to work.
A skill is a set of written instructions that teaches an AI how to do one job the way it should be done: review a pull request, plan a migration, write the release notes.
Install one here and it travels with your account into Claude, Claude Code, Cursor and every other client you sign in with.
Category: Security
1,738 results · page 16 of 58
- View details
release-reviewSkillSecurity
Senior developer-level release review for macOS/iOS apps. Identifies security, privacy, UX, and distribution issues with actionable fixes. Use when preparing an app for release, want a critical review, or before App Store submission.
Ready to connect★ 727
- View details
old-coder-apiSkillSecurity
Design, change, or review an HTTP/JSON API surface — endpoints, request/response shapes, authentication and authorization, pagination, idempotency, rate limits, versioning, and deprecations. Use when adding or modifying an HTTP endpoint, reviewing an OpenAPI spec or HTTP route diff, or deciding whet
Ready to connect★ 723
- View details
configurationSkillSecurity
Configuration patterns for .NET 10 applications. Covers the Options pattern, IOptionsSnapshot vs IOptions, secrets management, and environment-based configuration. Load this skill when setting up application configuration, managing secrets, binding configuration sections, or when the user mentions "
Ready to connect★ 707
- View details
cpg-analysisSkillSecurity
Deep code property graph analysis with Joern CPG (AST+CFG+PDG) and CodeQL for control flow, data flow, taint analysis, and security auditing
Ready to connect★ 707
- View details
outdatedSkillSecurity
Dependency health report for .NET solutions: outdated NuGet packages, vulnerable versions, and commercial-license traps (MediatR, MassTransit, FluentAssertions, AutoMapper) — powered by the get_nuget_packages MCP tool. Invoke when: "outdated packages", "check dependencies", "stale packages", "packag
Ready to connect★ 707
- View details
security-scanSkillSecurity
Deep security scanning for .NET applications across 6 layers: vulnerable packages, secrets detection, OWASP code patterns, auth configuration, CORS policy, and data protection. Produces severity-rated findings with specific remediation steps. Load this skill when: "security scan", "security audit",
Ready to connect★ 707
- View details
verifySkillSecurity
Run a comprehensive 7-phase verification pipeline for .NET projects: build, analyzers, antipattern detection, tests, security, formatting, and diff review. Each phase produces PASS/FAIL with actionable output and the pipeline short-circuits on critical failures. Also the authority on verification st
Ready to connect★ 707
- View details
bacen-compliance-sentinel-rafael-mastronardiSkillSecurity
Complete guidance on compliance with Central Bank of Brazil regulations: CMN Resolution No. 4,893/2021 (Cybersecurity Policy), BCB Resolution No. 85/2021 (GRSIC), Open Finance Brasil (BCB Resolutions No. 32/2020 and updates), and other BACEN prudential rules. Covers the elabora
Ready to connect★ 691
- View details
recipe-front-reviewSkillSecurity
Reviews completed frontend implementation for governing-source compliance, scope economy, repository quality, and security, then applies user-approved React corrections.
Ready to connect★ 681
- View details
recipe-reviewSkillSecurity
Reviews completed implementation for governing-source compliance, scope economy, repository quality, and security, then applies user-approved corrections.
Ready to connect★ 681
- View details
code-auditorSkillSecurity
Performs comprehensive codebase analysis covering architecture, code quality, security, performance, testing, and maintainability. Use when user wants to audit code quality, identify technical debt, find security issues, assess test coverage, or get a codebase health check.
Ready to connect★ 671
- View details
auth-checkerSkillSecurity
Audit authentication flows for security vulnerabilities
Ready to connect★ 661
- View details
clawdbot-securitySkillSecurity
Security audit and hardening for Clawdbot/Moltbot installations. Detects exposed gateways, fixes permissions, enables authentication, and guides firewall/Tailscale setup.
Ready to connect★ 661
- View details
firebase-cloud-firestoreSkillSecurity
Use when setting up Firestore, designing schemas, doing CRUD, creating listeners, paginating queries, configuring indexes, enabling offline persistence, or writing security rules.
Ready to connect★ 637
- View details
firebase-data-connectSkillSecurity
Lets your agent work with Firebase services like databases and authentication.
Ready to connect★ 637
- View details
cyberedge-correlate-cvesSkillSecurity
Correlate exact, evidence-backed CPE identities already observed by CyberEdge with normalized NVD CVE records. Use when an AI operator must run CVE intelligence for an authorized Scope, interpret CVSS metadata and lifecycle state, or distinguish completed CPE coverage from missing identity or provid
Ready to connect★ 614
- View details
cyberedge-discover-servicesSkillSecurity
Run controlled TCP connect service discovery through the CyberEdge Agent Protocol for an explicitly authorized Scope. Use when an AI agent must identify exposed baseline services on approved domain or IP targets; never use for ambiguous targets, vulnerability exploitation, arbitrary port ranges, or
Ready to connect★ 614
- View details
cyberedge-report-findingsSkillSecurity
Report and query evidence-backed security findings from authorized CyberEdge Tasks. Use for versioned scanner adapters that classify existing Observations, never for arbitrary command or PoC execution.
Ready to connect★ 614
- View details
cyberedge-scan-vulnerabilitiesSkillSecurity
Run and interpret CyberEdge's reviewed, bounded Nuclei vulnerability baseline for an explicitly authorized Scope. Use when an AI operator must execute versioned signed templates, wait for the Task, correlate normalized Findings with immutable scanner Evidence, or distinguish negative coverage from a
Ready to connect★ 614
- View details
better-auth-best-practicesSkillSecurity
Skill for integrating Better Auth - the comprehensive TypeScript authentication framework.
Ready to connect★ 611
- View details
councilSkillSecurity
Orchestrates multi-advisor council debates on high-impact architecture, technology, or product decisions. Dispatches 3-5 domain archetype subagents (pragmatic-engineer, architect-advisor, security-advocate, product-mind, devils-advocate, the-thinker) through opening statements, tensions, position ev
Ready to connect★ 611
- View details
electron-devSkillSecurity
Expert guide for Electron development with Electron Vite and Electron Builder. Use when developing Electron applications, working with main/renderer processes, IPC communication, preload scripts, security configuration, native module handling, or build/distribution setup.
Ready to connect★ 611
- View details
nw-agent-testingSkillSecurity
5-layer testing approach for agent validation including adversarial testing, security validation, and prompt injection resistance
Ready to connect★ 610
- View details
nw-security-by-designSkillSecurity
Security design principles, STRIDE threat modeling, OWASP Top 10 architectural mitigations, and secure patterns. Load when designing systems or reviewing architecture for security.
Ready to connect★ 610
- View details
qv-pr-reviewSkillSecurity
Deep-dive review of any GitHub PR in tetherto/qvac. Validates gitflow, CI, title/body format, code quality, security, and applicable repo rules. Posts a PENDING review with inline comments. Use when reviewing a PR, given a PR link, or invoking /qv-pr-review.
Ready to connect★ 601
- View details
goSkillSecurity
Zero-config goal-to-tasks engine. Takes any goal (software, pentest, business, learning), runs adaptive discovery, generates a validated spec, parses into TaskMaster tasks, creates an implementation plan, and executes with built-in CDD verification. Use when user says "PRD", "product requirements",
Ready to connect★ 596
- View details
prd-taskmasterSkillSecurity
Zero-config goal-to-tasks engine (the Atlas engine). Takes any goal (software, pentest, business, learning), runs adaptive discovery via brainstorming, generates a validated spec, parses into TaskMaster tasks, and hands off to execution. Use when user says "PRD", "product requirements", "I want to b
Ready to connect★ 596
- View details
Urban and demographic analysis of an unplanned peri-urban municipalitySkillSecurity
This skill provides a complete methodological framework for analyzing the spatial organization, demographic dynamics, service needs, vulnerability, and public policies of an unplanned peri-urban area.
Ready to connect★ 581
- View details
67-agency-vendor-briefSkillSecurity
Use when hiring OUTSOURCERS — agencies, freelancers, production houses, vendors: scope of work, deliverable specs, number of revision rounds, approval workflow, payment milestones, IP and security clauses, and a post-project vendor evaluation sheet. Triggered when the user mentions 'brief agency', '
Ready to connect★ 574
- View details
validate-changes-match-specsSkillSecurity
Validate that a branch or pull request implementation matches introduced product, technical, security, and related specs. Use when reviewing or finishing a spec-driven change and resolving mismatches between checked-in specs and implementation.
Ready to connect★ 567
What is a skill?
A skill is plain text, usually a SKILL.md file and the scripts it refers to, written for an AI rather than for a person. It carries the steps, the house rules and the examples a good answer needs, so you stop pasting the same briefing into every new chat.
52,524 of the 52,958 skills listed here can be served through ahel today, and they come from public repositories. Each one has its own page with the instructions themselves on it, so you can read what a skill will tell your AI to do before you install it.
Install one and every AI you use gets it
Installing a skill adds it to your gateway and turns it on in the same step. Claude Code surfaces it as a slash command; any client can read the full instructions with the skill_read tool.
Nothing is copied into a project folder. The instructions are served from your account, so the same skill is there in every AI you connect, and turning it off removes it from all of them at once.